Ciminion and Hydra are two recently introduced symmetric key Pseudo-Random Functions for Multi-Party Computation applications. For efficiency both primitives utilize quadratic permutations at round level. Therefore, polynomial system solving-based attacks pose a serious threat to these primitives. For Ciminion we construct a quadratic degree reverse lexicographic (DRL) Gr\"obner basis for the iterated polynomial model via affine transformations. For Hydra we provide a computer-aided proof in SageMath that a quadratic DRL Gr\"obner basis is already contained within the iterated polynomial system for the Hydra heads after affine transformations and a linear change of coordinates. Our Ciminion DRL Gr\"obner basis simplifies cryptanalysis, since one does not need to impose genericity assumptions, like being regular or semi-regular, anymore to derive complexity estimates on key recovery attacks. In the Hydra proposal it was claimed that $r_\mathcal{H} = 31$ rounds for the heads are sufficient to achieve $128$ bits of security against Gr\"obner basis attacks for key recovery. However, for $r_\mathcal{H} = 31$ standard term order conversion to a lexicographic (LEX) Gr\"obner basis for our Hydra DRL Gr\"obner basis requires just $126$ bits. Moreover, via the Eigenvalue Method up to $r_\mathcal{H} = 33$ rounds can be attacked below $128$ bits.
翻译:Ciminion和Hydra是近期提出的两种面向多方计算应用的对称密钥伪随机函数。为提升效率,这两种原语均在轮层级采用二次置换,因此基于多项式系统求解的攻击对其构成严重威胁。针对Ciminion,我们通过仿射变换为迭代多项式模型构造了二次逆字典序(DRL)Gröbner基。针对Hydra,我们利用SageMath提供计算机辅助证明,表明经过仿射变换与线性坐标变换后,Hydra头部的迭代多项式系统已包含二次DRL Gröbner基。本文构造的Ciminion DRL Gröbner基简化了密码分析过程——无需再施加正则性或半正则性等通用性假设即可推导密钥恢复攻击的复杂度估计值。在Hydra方案中,研究者声称头部迭代轮数$r_\mathcal{H} = 31$即可实现针对Gröbner基密钥恢复攻击的128比特安全性。然而,当$r_\mathcal{H} = 31$时,将本文Hydra DRL Gröbner基转换为字典序(LEX)Gröbner基的标准项序转换仅需126比特。此外,通过特征值方法可对至多$r_\mathcal{H} = 33$轮的迭代实施低于128比特的攻击。